Plugin info

Total downloads: 1,048
Active installs: 40
Total reviews: 0
Average rating: 0
Support threads opened: 0
Support threads resolved: 0 (0%)
Available in: 1 language(s)
Contributors: 1
Last updated: 12/16/2020 (1841 days ago)
Added to WordPress: 12/16/2020 (5 years old)
Minimum WordPress version: 4.7
Tested up to WordPress version: 5.5.17
Minimum PHP version: 7.2

Maintenance & Compatibility

Maintenance score

Possibly abandoned • Last updated 1841 days ago

20/100

Is Disable User Enumeration abandoned?

Possibly abandoned (last update 1841 days ago).

Compatibility

Requires WordPress: 4.7
Tested up to: 5.5.17
Requires PHP: 7.2

Similar & Alternatives

Explore plugins with similar tags, and compare key metrics like downloads, ratings, updates, support, and WP/PHP compatibility.

No similar plugins found yet.

Description

User enumeration can be use for brute-force techniques to either guess or confirm valid users in a system. User enumeration is often a web application vulnerability, though it can also be found in any system that requires user authentication.

An enumeration attack allows a hacker to check whether a name exists in the database. For example, to set up a brute-force attack, rather than searching through login and password pairs, all they need is a matching password for a verified user name, saving time and effort.

The phrase “username harvesting” refers to a vulnerability that when exploited allows people or programs interacting with an application to determine what a valid username is vs an invalid username.

**You can check your site have user enumeration by simply type https://selectedfirms.co/wp-json/wp/v2/users that’s it. **

Features:

  1. We only disable for non logged in users.
  2. You can deactivate with single click. No extra configuration required.
  3. Something else about the plugin

Installation

Either using the dashboard ‘Add Plugin’ feature to find, install and activate the plugin

  1. Download and the plugin from the download link
  2. Upload the entire plugin directory to your website’s /wp-contents/plugins/ using a file manager or FTP
  3. Activate the plugin through the Plugins menu

Frequently Asked Questions

How to check plugin works?

You just need to run in browser to verify <youdomin.com>/wp-json/wp/v2/users.

I have active plugin, why its still display user data in response.

Just double check to make sure, you are not logged in. This plugin won’t do anything for logged in users, it only works when you are logged out.

What about settings?

There are no settings required. We are focus on only user enumerations. Only activation is enough.

Is it change anything in database?

Plugin is work standalone. Its not required any database operations.

Review feed

No reviews available

Screenshots

  1. Activate plugin.

    Activate plugin.

  2. Restriction applied on username.

    Restriction applied on username.

Changelog

0.1

  • Initial release.